From the course: Governance, Risk, and Compliance (GRC) Essentials by Pearson

Unlock this course with a free trial

Join today to access over 25,200 courses taught by industry experts.

Reviewing and submitting documentation

Reviewing and submitting documentation

Submitting accurate and complete documentation is an important step in demonstrating compliance and guaranteeing the success of your audit or assessment. In this lesson, we'll cover what documentation is required, how to review it, and best practices. Let's start by identifying what should be included in your compliance documentation. Each compliance framework or regulation may have unique requirements, but here are the key components generally expected in most submissions. First is you should submit policies and procedures that outline your organization's governance and security operational standards. When it comes to system documentation, this can include network diagrams, data flow maps, architectural diagrams that detail the system being assessed. You might be asked to submit logs and reports that evidence your control implementation and monitoring capabilities. If you've performed any risk assessments, definitely include that to showcase how your organization is identifying and…

Contents